Insider Threat Matrix™Insider Threat Matrix™
  • ID: DT106
  • Created: 14th December 2024
  • Updated: 23rd July 2026
  • Contributor: The ITM Team

Microsoft Entra ID Privileged Identity Management Resource Audit

Within the Microsoft Entra admin center, the Resource audit can be reviewed to identify PIM elevations for users, including key information such as the requestor user, subject user, action, domain, and primary target (role assigned/removed). This can aid investigators by providing an audit trail for PIM elevations and the duration for which an eligible role was attached to a user account.

 

The following URL can be used to view this activity log, provided the investigator's account has the Privileged Role Administrator role assigned, or a role with higher privileges: https://entra.microsoft.com/#view/Microsoft_Azure_PIMCommon/ResourceMenuBlade/~/Audit/resourceId//resourceType/tenant/provider/aadroles

Sections

ID Name Description
PR024Privilege Elevation

The subject activates, obtains, or creates an execution, identity, or authorization context that provides greater effective access than their normal operating context. The elevated context may be available through permissions legitimately assigned to the subject, or obtained through misuse, circumvention, identity manipulation, credential acquisition, or exploitation of a technical vulnerability.

 

Privilege elevation is preparatory where it increases the subject’s capability to access restricted systems or data, modify protected configurations, disable controls, or perform a later infringement. Routine elevation conducted for an approved and attributable operational task should not be classified under this Section. Investigators should assess whether the mechanism was available to the subject, whether its activation was approved, and how the elevated context was subsequently used.

PR018Circumventing Security Controls

A subject abuses their access or conducts unapproved changes to circumvent security controls.

IF011Providing Access to a Unauthorized Third Party

A subject intentionally provides system or data access to a third party that is not authorized to access it.

PR015.004Bulk Email Collection

A subject creates an email collection file such as a Personal Storage Table (PST) file or an MBOX file to copy an entire mailbox or subset of a mailbox containing sensitive information.

ME024.002Access to Privileged Groups and Non-User Accounts

A subject with access to privileged groups (e.g., Domain Admins, Enterprise Admins, or Security Groups) or non-user accounts (such as service accounts, application identities, or shared mailboxes) gains elevated control over systems, applications, and sensitive organizational data. Access to these groups or accounts often provides the subject with knowledge of security configurations, user roles, and potentially unmonitored or sensitive activities that occur within the system.

 

Shared mailboxes, in particular, are valuable targets. These mailboxes are often used for group communication across departments or functions, containing sensitive or confidential information, such as internal discussions on financials, strategic plans, or employee data. A subject with access to shared mailboxes can gather intelligence from ongoing conversations, identify targets for further exploitation, or exfiltrate sensitive data without raising immediate suspicion. These mailboxes may also bypass some security filters, as their contents are typically considered routine and may not be closely monitored.

 

Access to privileged accounts and shared mailboxes also allows subjects to escalate privileges, alter system configurations, access secure data repositories, or manipulate security settings, making it easier to both conduct malicious activities and cover their tracks. Moreover, service and application accounts often have broader access rights across systems or environments than typical user accounts and are frequently excluded from standard monitoring protocols, offering potential pathways for undetected exfiltration or malicious action.

 

This elevated access gives subjects insight into critical system operations and internal communications, such as unencrypted data flows or internal vulnerabilities. This knowledge not only heightens their potential for malicious conduct but can also make them a target for external threat actors seeking to exploit this elevated access.

IF039.002Access to a Retained Former Account

A subject accesses or uses an account that was previously issued to them by the organization but is no longer authorized for their use. This may occur after employment has ended, a contract has expired, a role has changed, a project has concluded, or access has otherwise ceased to be permitted.

 

This behavior may involve the subject using retained credentials, active sessions, multi-factor authentication enrollment, recovery options, device trust, federated access, cached authentication material, or connected service access after authorization has ended. The defining behavior is that the subject continues to access an account that they were once permitted to use but are no longer authorized to access.

PR024.002Privilege Activation

The subject activates elevated permissions that are assigned to them or conditionally available through an established organizational or operating-system mechanism. This may include sudo, an elevation prompt, just-in-time access, privileged identity management, cloud role assumption, or an equivalent governed process.

 

The activation may itself be approved or unapproved. It should be recorded where entering the elevated context is materially relevant to an investigation, including where an approved mechanism is used outside its authorized purpose or before a later infringement.